Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
CLOUD

AWS IAM policy best practices: least privilege without the pain

How to write secure AWS IAM policies: least privilege, roles instead of access keys, permission boundaries, SCPs, conditions and IAM Access Analyzer.

By VISIBI Cloud team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·11 min read
QUICK ANSWER

How to write secure AWS IAM policies: least privilege, roles instead of access keys, permission boundaries, SCPs, conditions and IAM Access Analyzer.

KEY TAKEAWAYS
✓Use IAM roles and temporary credentials — avoid long-lived access keys.
✓Start from AWS managed policies, then tighten with IAM Access Analyzer.
✓Use AWS Organizations SCPs as guardrails across all accounts.
✓Protect the root user with MFA and never use it day-to-day.

How IAM policies are evaluated

An IAM request is allowed only if an identity or resource policy explicitly allows it and nothing explicitly denies it. Explicit deny always wins. Service control policies (SCPs) and permission boundaries set the maximum permissions — they never grant access on their own.

RELATED GUIDE12 proven ways to reduce your AWS bill →

1. Prefer roles and short-lived credentials

Give people access through IAM Identity Center (single sign-on) and give workloads IAM roles (EC2 instance profiles, ECS task roles, Lambda execution roles). Temporary credentials expire automatically, so leaked keys are far less dangerous.

2. Apply least privilege

  • Start with AWS managed job-function policies, then narrow down
  • Use IAM Access Analyzer to generate policies from CloudTrail activity
  • Scope Resource to specific ARNs instead of “*”
  • Review “last accessed” data and remove unused permissions
Want an AWS security review?Certified AWS architects review your IAM, network and logging against the Well-Architected Framework.Book a free AWS consultation →

3. Use conditions

Conditions make policies much safer. Common examples: require MFA (aws:MultiFactorAuthPresent), restrict by source VPC or IP (aws:SourceVpc, aws:SourceIp), enforce tags (aws:ResourceTag) and limit regions (aws:RequestedRegion).

4. Guardrails with SCPs and permission boundaries

In AWS Organizations, SCPs stop anyone — even administrators — from doing things like disabling CloudTrail, leaving the organisation or using unapproved regions. Permission boundaries let developers create roles without being able to escalate their own privileges.

5. Monitor and audit

  • Enable CloudTrail in every account and region
  • Turn on IAM Access Analyzer for external and unused access
  • Use AWS Config rules and Security Hub for IAM checks
  • Manage IAM in Terraform so every change is reviewed

Common mistakes to avoid

✕Buying commitments before rightsizing
✕No tagging, so nobody knows who owns the spend
✕Click-ops changes that can’t be reproduced or audited
✕Migrating without a rollback plan
HOW VISIBI CAN HELP

How we help with cloud

01AssessCertified architects review cost, security and reliability.
02PlanA prioritised roadmap with savings and risks quantified.
03ImplementChanges delivered as Terraform with zero-downtime rollout.
04OperateFinOps reviews, monitoring and optional 24/7 managed services.
Book a free AWS consultation →Free · No obligation · Reply within 24 hours

Frequently asked questions

What is least privilege in AWS?

Granting only the permissions needed for a task, on only the resources needed, for only as long as needed.

Should I use IAM users?

For people, AWS recommends IAM Identity Center instead of IAM users. For workloads, use roles.

What is the difference between an SCP and an IAM policy?

An SCP sets the maximum permissions for accounts in an organisation; IAM policies grant permissions within that limit.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Cloud team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

CLOUD · 10 MIN12 proven ways to reduce your AWS billRead →CLOUD · 7 MINFinOps for beginners: how to control cloud costs as you growRead →CLOUD · 8 MIN10 ways to cut your Azure billRead →
FREE · NO OBLIGATION

Want an AWS security review?

Certified AWS architects review your IAM, network and logging against the Well-Architected Framework.

Book a free AWS consultation →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
CLOUD SAVINGS ESTIMATEEXAMPLE
Your bill, line by line
Idle & oversized compute£2,300/mo
Uncommitted steady usage£1,150/mo
Est. total saving31%
Your free review shows your real numbers.